coinpaprika-api
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions include adding an external Model Context Protocol (MCP) server (https://mcp.coinpaprika.com/sse) and installing a plugin via a marketplace command. These operations connect the agent to services provided by a well-known cryptocurrency data platform.
- [INDIRECT_PROMPT_INJECTION]: The skill processes unstructured data from external API responses, such as coin descriptions, search results, and event listings, which provides a surface for indirect prompt injection.
- Ingestion points: Data returned by tools such as
getCoinById,search, andgetCoinEventsfrom the mcp.coinpaprika.com server. - Boundary markers: No specific delimiters or instructions to ignore embedded commands are present in the provided skill text.
- Capability inventory: The skill allows the agent to query a wide range of market and coin metadata via 29 specialized MCP tools.
- Sanitization: No sanitization or filtering logic is specified for the text content received from the API.
Audit Metadata